Query Batching Vulnerability in Saleor E-Commerce Platform
CVE-2026-33756

7.5HIGH

Key Information:

Vendor

Saleor

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-33756?

The Saleor E-Commerce Platform suffers from a resource exhaustion vulnerability due to inadequate enforcement of limits on query batching. Attackers can send a single HTTP request containing numerous GraphQL operations, circumventing the complexity limits and potentially overwhelming system resources. This issue affects versions 2.0.0 up to but not including 3.23.0a3, along with specific patch versions. Updating to the fixed versions is critical to enhance the security and stability of your e-commerce application.

Affected Version(s)

saleor >= 2.0.0, < 3.20.118 < 2.0.0, 3.20.118

saleor >= 3.21.0-a.0, < 3.21.54 < 3.21.0-a.0, 3.21.54

saleor >= 3.22.0-a.0, < 3.22.47 < 3.22.0-a.0, 3.22.47

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.